Cybatar Security Hub
Threat Intelligence / Intelligence quality
Threat-intelligence guide

Threat Intelligence Quality, Confidence & Decision Usefulness

How should a security team judge whether threat intelligence is useful?

Direct answer

Judge intelligence by whether its provenance is understood, the underlying evidence can be distinguished from analysis, it is timely for the decision, sufficiently specific to the environment, appropriately caveated, corroborated where material and connected to an operational decision. A large feed or high confidence label is not proof of quality.

External reference

National Institute of Standards and Technology (NIST) — SP 800-150 — Guide to Cyber Threat Information Sharing

NIST guidance emphasises goals, sources, sharing rules and effective use of cyber threat information. The quality dimensions on this page are a Cybatar-authored operational method, not a NIST scoring standard.

Primary source →

Operational method

Step 1

Check provenance

Know the originating source, collection method where available, redistribution constraints and whether the intelligence is primary, secondary or derived analysis.

Step 2

Separate observation from assessment

Keep factual observations, inferred relationships and attribution/confidence judgements distinguishable.

Step 3

Check timeliness

Record creation, observation, receipt and last-reviewed times so the consumer can judge whether the intelligence is still decision-relevant.

Step 4

Check environmental relevance

Relate intelligence to technologies, identities, services, geography, sector, exposures or incidents that actually affect the organisation.

Step 5

Measure decision impact

Record whether the intelligence changed monitoring, hunting, remediation, incident response or risk treatment. Useful intelligence should support a traceable decision or hypothesis.

Relevant Cybatar sources

Claim boundary

The Cybatar quality method is first-party guidance. It is not an intelligence-provider rating standard, does not establish source truthfulness and cannot remove uncertainty from threat attribution.

These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.

Related operating resources